Documentation and release notes are strong, and the repository shows recent multi-contributor activity. The single publisher, concentrated commits, missing security policy, and unpinned workflow actions leave modest continuity and build-integrity concerns.
84%
Total Score
67
100
100
83
Only one registry publishing account is listed. The linked repository is user-owned rather than organization-owned, so there is limited visible publishing redundancy.
Although 4 contributors were active, one contributor made about 89% of recent commits, leaving maintenance substantially dependent on one person.
The repository has no published security policy, leaving vulnerability reporting and response expectations less transparent despite the presence of security scanning tooling.
Both workflows were analyzed without high-confidence audit findings or untrusted triggers, but all 12 action references are unpinned, so workflow dependencies can change unexpectedly.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.